Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 871

nvd логотип

CVE-2022-1433

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-1433

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2022-1428

около 4 лет назад

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1428

около 4 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1426

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
EPSS: Низкий
debian логотип

CVE-2022-1426

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2
EPSS: Низкий
nvd логотип

CVE-2022-1406

около 4 лет назад

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1406

около 4 лет назад

Improper input validation in GitLab CE/EE affecting all versions from ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1352

около 4 лет назад

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1352

около 4 лет назад

Due to an insecure direct object reference vulnerability in Gitlab EE/ ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1428

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1428

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1426

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1426

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from ...

CVSS3: 6.5
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/ ...

CVSS3: 5.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться